Files
tool-evaluator/docker-compose.yml
opencode db397a14bc
Build & Push Docker Image / build (push) Successful in 4m32s
fix: security hardening, validation, cache and analytics fixes
Backend security:
- Admin-gate /admin/redundancy (GET+POST) with zod validation and tool existence checks
- Restrict CORS to same-origin (plus CORS_ORIGIN allowlist) and SameSite=Lax cookie
- Validate returnTo to prevent open redirect in the OIDC flow
- Validate/coerce relations body, reject self-relations and non-admin 'recommended'
- Add central JSON error middleware (no more Express HTML 500s)
- Fail fast at startup when SESSION_SECRET/VOTER_SECRET missing in production

Backend correctness:
- Stop leaking voterToken in the create-rating response
- Allow clearing websiteUrl/iconUrl (nullable in UpdateToolBody, frontend sends null)
- Regenerate session after login/callback (session fixation) and add OIDC state check
- Block self-demotion and last-admin demotion in user PATCH
- Set created_by to NULL on user delete (FK-safe)
- Validate cost create/update bodies with zod
- Unique index (tool_id, voter_token) + 409 on race duplicate ratings
- Clamp audit limit, escape ilike wildcards in search, O(N) analytics queries

Frontend:
- tools-browse reads and syncs URL query params (fixes home 'View all' links)
- Invalidate analytics/top-tools/categories/features caches after mutations
- Sync category combobox input when the value changes externally
- Hide Write a Review for anonymous users, drop unreachable rating guard
2026-08-01 19:11:00 +02:00

35 lines
795 B
YAML

services:
db:
image: postgres:16-alpine
environment:
POSTGRES_USER: toolrate
POSTGRES_PASSWORD: toolrate
POSTGRES_DB: toolrate
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U toolrate"]
interval: 5s
timeout: 5s
retries: 5
app:
build: .
ports:
- "8080:8080"
environment:
PORT: "8080"
BASE_PATH: "/"
DATABASE_URL: postgres://toolrate:toolrate@db:5432/toolrate
SESSION_SECRET: change-this-to-a-random-secret
VOTER_SECRET: change-this-to-a-random-voter-secret
NODE_ENV: production
LOCAL_ADMIN_USERNAME: admin
LOCAL_ADMIN_PASSWORD: pssw0rd
depends_on:
db:
condition: service_healthy
volumes:
pgdata: